At a Glance
- Tasks: Design and implement cutting-edge security solutions for privileged access management and public key infrastructure.
- Company: Join Universal Music Group, the leading music-based entertainment company in the UK.
- Benefits: Enjoy competitive salary, private medical insurance, and 25 days of annual leave.
- Other info: Diverse and inclusive workplace committed to embracing all talents and backgrounds.
- Why this job: Make a real impact in securing identities while working in a dynamic and creative environment.
- Qualifications: 5+ years in IAM or Security Engineering with strong CyberArk and PKI experience.
The predicted salary is between 60000 - 80000 £ per year.
Music is Universal
It’s the passionate and dedicated team at Universal Music who help make us the world’s leading music company.
From A&R to finance, legal to digital, sales to marketing, Universal Music is the place to grow and develop your career within a truly commercial and innovative business that leads in everything it does.
Everyone is welcome to apply for our roles, and we are determined to ensure that no applicant or employee receives less favourable treatment because of gender, race, disability, sexual orientation, religion, belief, age, marital status, background, pregnancy, or caring responsibilities.
We also recognise the importance of diversity of thought within our teams and are fully committed to embracing the talents of people with autism, dyslexia, ADHD, and other forms of neurocognitive variation.
We will always seek to make appropriate adjustments to recruitment, workplaces, and work processes to be fully inclusive to people with different needs and working styles.
If you need us to make any reasonable adjustments for you from application onwards, including alternatives to the online form or to disclose a neurocognitive condition, please email
Job Summary
We are currently seeking an Identity & Access Management Engineer with deep specialization in Privileged Access Management (PAM) and Public Key Infrastructure (PKI) to join UMG’s global Tech Security & Identity organization.
Reporting to the VP, Tech Security & Identity, this role is a hands‑on engineering position focused on designing, implementing, and operating enterprise‑grade PAM and PKI capabilities across a complex, global environment.
This engineer will play a critical role in securing privileged identities, service accounts, machine identities, and cryptographic trust across on‑premises and cloud platforms.
The position emphasizes technical execution, automation, and operational excellence, partnering closely with infrastructure, security, and application teams to reduce risk, improve resilience, and scale identity security services.
The ideal candidate brings strong Cyber Ark and PKI experience, an automation‑first mindset, and the ability to operate effectively in a regulated, highly distributed enterprise.
- Job Functions
- Design, engineer, deploy, and operate Privileged Access Management solutions, with primary responsibility for Cyber Ark platforms including Vault, CPM, PVWA, PSM, and related integrations.
- Implement and manage PAM controls for human and non‑human identities, including privileged users, service accounts, application credentials, and secrets.
- Engineer and support enterprise PKI services, including certificate issuance, renewal, revocation, and lifecycle automation across infrastructure, applications, and end‑user devices.
- Administer and enhance PKI platforms and services such as Microsoft AD Certificate Services (ADCS), public certificate authorities, and certificate lifecycle management tools.
- Develop and maintain automation for PAM and PKI workflows using scripting and infrastructure‑as‑code approaches (Power Shell, Python, Terraform, APIs).
- Partner with application, cloud, and infrastructure teams to integrate PAM and PKI capabilities into platforms, CI/CD pipelines, and operational processes.
- Define and enforce privileged access policies, credential management standards, and cryptographic controls aligned to security, audit, and compliance requirements.
- Troubleshoot and resolve complex PAM and PKI incidents, including certificate outages, access failures, and privileged session issues.
- Contribute to operational readiness, monitoring, and audit support activities related to PAM and PKI controls (e. g., SOX, ISO 27001, internal audits).
- Maintain technical documentation, runbooks, and configuration standards to support scalable and repeatable operations.
- Continuously evaluate opportunities to improve security posture, resilience, and efficiency through automation, tooling enhancements, and process optimization.
- Job Requirements
Essential Qualifications
- 5+ years of hands‑on experience in Identity & Access Management or Security Engineering roles, with strong focus on Privileged Access Management and/or PKI.
- Demonstrated experience engineering and operating Cyber Ark PAM solutions in an enterprise environment.
- Strong hands‑on experience with PKI concepts and technologies, including certificate lifecycle management, trust models, and cryptographic standards.
- Experience administering Microsoft AD Certificate Services (ADCS) and managing public SSL/TLS certificates.
- Proficiency in scripting and automation using tools such as Power Shell and Python; experience with infrastructure‑as‑code or API‑based integrations preferred.
- Solid understanding of identity, authentication, and access control concepts, particularly as they relate to privileged and machine identities.
- Experience working in hybrid and cloud environments (Azure and/or AWS) integrating PAM and PKI controls.
- Ability to work independently on complex technical problems while collaborating effectively within a global, cross‑functional team.
- Strong troubleshooting, documentation, and communication skills, with the ability to explain technical issues to non‑specialist stakeholders.
Desirable Qualifications
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical discipline.
- Experience with certificate management platforms such as Keyfactor or Venafi.
- Experience integrating PAM or PKI into CI/CD pipelines, Dev Ops tooling, or secrets management solutions.
- Familiarity with identity and security compliance frameworks such as SOX, ISO 27001, NIST, or similar.
- Professional certifications such as Cyber Ark Defender, Microsoft Certified: Identity and Access Administrator, Security+, CISSP, or similar.
- Experience operating IAM or security services within a large, global, or highly regulated enterprise environment.
- About UMG UK
We are Universal Music Group UK – the UK’s leading music‑based entertainment company.
We exist to shape culture through the power of artistry.
We help UK artists produce, distribute and promote the most critically acclaimed and commercially successful music to inspire and entertain fans at home and around the world.
- Bonus Tracks: Your Benefits
- Group Personal Pension Scheme (between 3% and 9%)
- Private Medical Insurance
- 25 paid days of annual leave
- Interest Free Season Ticket Loan
- Holiday Purchase scheme
- Dental and Travel Insurance options
- Cycle to Work Scheme
- Salary Sacrifice Cars
- Subsidised Gym Membership
- Employee Discounts (Reward Gateway)
- Just So You Know…
The company presents this job description as a guide to the major areas and duties for which the jobholder is accountable.
However, the business operates in an environment that demands change and the jobholder’s specific responsibilities and activities will vary and develop.
Therefore, the job description should be seen as indicative and not as a permanent, definitive, and exhaustive statement.
- Job Category: Universal Music Group
- #J-18808-Ljbffr
IAM Engineer - PAM & PKI in London employer: Praca50.plus
At Universal Music, we pride ourselves on being an inclusive and innovative employer, where your career as a Senior UK Data Analyst can truly flourish. Our vibrant work culture encourages collaboration and creativity, offering ample opportunities for professional growth while working on exciting projects that shape the music industry. With a commitment to diversity and support for neurodiverse individuals, we ensure that every team member feels valued and empowered to contribute their unique talents.
StudySmarter Expert Advice🤫
We think this is how you could land IAM Engineer - PAM & PKI in London
✨Get Involved in the Cybersecurity Community
Diving into the cybersecurity community is key for landing that full-time gig. Join forums like Reddit's r/cybersecurity or attend local meetups to connect with industry veterans and other job seekers. Networking is everything in this field—don’t just be a passive lurker!
✨Show Off Your Skills with Capture the Flag Competitions
Participate in Capture the Flag (CTF) competitions; these are not just a fun way to boost your skills but also a chance to showcase your talent to potential employers. Many companies, including Praca50.plus, love seeing candidates who actively engage in these challenges.
✨Tailor Your Online Presence
Make sure your LinkedIn and any professional profiles reflect your cybersecurity expertise. Share your projects, whether they’re personal or from a previous role, to catch the eye of hiring managers. This is how they’ll find your passion and commitment to the field!
✨Apply Directly Through Praca50.plus
Don’t forget to head straight to our website and check out any openings for cybersecurity roles at Praca50.plus. Applying directly can sometimes give you an edge, especially if you can mention that you've been following our work or engaging in the community.
We think you need these skills to ace IAM Engineer - PAM & PKI in London
Some tips for your application 🫡
Show off your technical skills:In cybersecurity, it's crucial to highlight your technical prowess. Make sure your CV showcases specific skills like network security, penetration testing, or threat analysis. If you have relevant certifications (like CEH or CISSP), pop those on the front page to grab attention!
Tailor your portfolio for the role:Even for a full-time role, a portfolio can set you apart. If you've worked on any cybersecurity projects—be it CTF challenges, security assessments, or research papers—include these in your application. This demonstrates not just your skills, but also your hands-on experience!
Use real-world examples:When writing your cover letter, don’t just stick to your qualifications. Share real-world examples of how you’ve tackled security issues or vulnerabilities. This gives the hiring team at Praca50.plus insight into your practical problem-solving abilities and makes your application memorable.
Demonstrate your passion for cybersecurity:Cybersecurity is an ever-evolving field, so show us that you’re always learning! Mention any recent courses, webinars, or industry events you’ve attended. This not only exhibits your enthusiasm but also signals to Praca50.plus that you’re committed to staying ahead in the game.
How to prepare for a job interview at Praca50.plus
✨Sharpen Your Technical Skills
For a role in cybersecurity, it’s essential to be up-to-date with the latest tools and techniques. Brush up on your knowledge of firewalls, intrusion detection systems, and vulnerability assessment tools. Be ready to discuss specific scenarios where you’ve applied these skills, as hands-on experience can really set us apart in interviews.
✨Prepare for Scenario-Based Questions
Expect the interviewers at Praca50.plus to throw in some hypothetical situations to see how you’d handle them. Think about common security breaches or incidents and be prepared to explain how you would respond. This not only shows your problem-solving skills but also your understanding of real-world cybersecurity challenges.
✨Highlight Your Certifications
Certifications like CompTIA Security+, CISSP, or CEH can give you a significant edge in a full-time role in cybersecurity. Make sure to mention these during your interview and be prepared to discuss what you learned through those certifications and how they relate to the position at Praca50.plus.
✨Show Your Passion for Cybersecurity
Since you’re going for a full-time gig, showing genuine enthusiasm for the field can make all the difference. Share any personal projects, blogs, or communities you’re part of that relate to cybersecurity. This not only showcases your passion but also your commitment to staying engaged in this ever-evolving field.